07fly operates a modestly represented content-management and customer-relationship-management platform portfolio that skews toward serious outcomes, with a meaningful share of its vulnerabilities reaching critical severity. The recurrent exposure across its CMS and CRM products centers on web-application layer weaknesses including cross-site request forgery, unrestricted file upload, cross-site scripting, SQL injection, and missing authorization checks—patterns characteristic of input validation and access-control gaps in web-facing applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 07fly over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25379CRITICAL Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component. | Feb 28, 2025 | 9.6 | 26 | NO | NO |
CVE-2023-5020CRITICAL A vulnerability, which was classified as critical, has been found in 07FLY CRM V2. This issue affects some unknown processing of the file /index.php/sysmanage/Login/login_auth/ of | Sep 17, 2023 | 9.8 | 26 | NO | NO |
CVE-2024-9904HIGH A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pict | Oct 13, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-9903HIGH A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The | Oct 12, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-9855HIGH A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/ | Oct 11, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-3058MEDIUM A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipula | Jun 2, 2023 | 5.4 | 19 | NO | NO |
CVE-2025-7078MEDIUM A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site r | Jul 6, 2025 | 4.3 | 16 | NO | NO |
CVE-2024-51156MEDIUM 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'. | Nov 14, 2024 | 4.7 | 16 | NO | NO |
CVE-2024-51157MEDIUM 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html. | Nov 8, 2024 | 4.7 | 16 | NO | NO |
CVE-2024-9856MEDIUM A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System | Oct 11, 2024 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 07fly.
Media articles that mention a CVE ID that affects a product developed by 07fly — matched by CVE ID, not by vendor name.